Feeds

Boffin: Android's on-board malware scanner utterly FAILS

App blocker detects just 15% of malware

Seven Steps to Software Security

Google has added new anti-malware capabilities to Android 4.2 "Jelly Bean," but relying on them to block malicious apps might not be a good idea, says a computer science boffin from North Carolina State University.

The latest Android – currently only found on a select group of handsets – includes an on-device "application verification service" that claims to be able to alert users of potentially harmful apps and block their installation, irrespective of where they came from.

Associate professor Xuxian Jiang wanted to know how well the new feature fared against known Android malware, and to that end he pitted it against a collection of samples obtained by the university's Android Malware Genome Project.

The results? Not so good. Of the 1,260 samples tested, Android's on-device malware checker only managed to spot 193 of them, for a paltry detection rate of just 15.3 per cent.

That's bad news for Android users, as the instance of malware attacks on the platform has reportedly been growing – a point that Microsoft, in particular, has been using to flog its own, rival smartphone platform.

Jiang went on to pit the same sample collection against an assortment of ten Android-based antivirus engines. Without naming any of the products involved, Jiang reports that all of them fared significantly better than Jelly Bean's built-in one, with even the poorest performer catching 50 per cent of the malware.

Dialog box displayed by Android 4.2 when it spots potential malware

Even in Android 4.2 you won't be seeing this very often

Those are better findings than those reported in March by AV-Test, which reckoned that only about a third of the malware scanners for Android were actually up to the task.

Why such a poor showing for Google's product? According to Jiang, Jelly Bean's app verification service relies on relatively few data points to decide whether or not to block a given app install.

"Specifically, our study indicates that the app verification service mainly uses an app's SHA1 value and the package name to determine whether it is dangerous or potentially dangerous," he writes. "This mechanism is fragile and can be easily bypassed. It is already known that attackers can change with ease the checksums of existing malware (e.g., by repackaging or mutating it)."

Jiang further observes that Google has not integrated VirusTotal – a file-scanning security service which it bought in September – into the Android platform, but that VirusTotal performed significantly better than the app verification service in Jiang's tests.

Although Jiang notes that some form of malware checking more sophisticated than Jelly Bean's on-device method is necessary, however, he cautions that a delicate balance must be struck between security, device performance, and user privacy.

What's more, Jiang is quick to point out that the fact that Google is paying attention to Android security at all is welcome news. Prior to Android 4.2 – which is running on just 0.8 per cent of the devices out there, according to Google's stats – Android devices included no on-board security features at all.

Instead, they have relied on app stores to screen out malware, a method that researchers have shown doesn't always work. ®

Mobile application security vulnerability report

More from The Register

next story
Yorkshire cops fail to grasp principle behind BT Fon Wi-Fi network
'Prevent people that are passing by to hook up to your network', pleads plod
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
Mozilla fixes CRITICAL security holes in Firefox, urges v31 upgrade
Misc memory hazards 'could be exploited' - and guess what, one's a Javascript vuln
NEW, SINISTER web tracking tech fingerprints your computer by making it draw
Have you been on YouPorn lately, perhaps? White House website?
BMW's ConnectedDrive falls over, bosses blame upgrade snafu
Traffic flows up 20% as motorway middle lanes miraculously unclog
LibreSSL RNG bug fix: What's all the forking fuss about, ask devs
Blow to bit-spitter 'tis but a flesh wound, claim team
Attackers raid SWISS BANKS with DNS and malware bombs
'Retefe' trojan uses clever spin on old attacks to grant total control of bank accounts
Manic malware Mayhem spreads through Linux, FreeBSD web servers
And how Google could cripple infection rate in a second
prev story

Whitepapers

Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
Reducing security risks from open source software
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Consolidation: the foundation for IT and business transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.